Vulnerability management
The National Cybersecurity Centre (NCSC) is part of the global network for the management of IT system vulnerabilities. This means that the NCSC, as a specialist body, is permitted to assign a unique identification number to reported vulnerabilities in accordance with the international reference system. The NCSC has been authorised to do so by the competent independent US organisation, MITRE.
Reporting a vulnerability (Coordinated Vulnerability Disclosure CVD)
Have you discovered a vulnerability in an IT system or in commercially available applications, software or hardware impacting Switzerland and want to report it? There are different ways to report a vulnerability.

Framework conditions and rules
The discovery and reporting of vulnerabilities can have civil and criminal consequences. The associated risks can be reduced if you follow these rules.

CVE records
As part of its CNA duties, the NCSC maintains a catalog of CVE records published under its authority.

CVD cases
The NCSC documents vulnerabilities processed through the NCSC Coordinated Vulnerability Disclosure program, that have been approved for publication under the Information Security Act (ISG) Art. 73c Abs. 2.